Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues with routing…

    Scheduled Pinned Locked Moved Routing and Multi WAN
    20 Posts 4 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD Offline
      Derelict LAYER 8 Netgate
      last edited by

      Get rid of that WH NAT rule.  It's nonsensical.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • S Offline
        Slicster
        last edited by

        @Derelict:

        Get rid of that WH NAT rule.  It's nonsensical.

        I agree but if I remove that WH NAT rule, it breaks everything and I can't even ping the HP 5500 L3 interface.  It's a weird one.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          It's wrong.  Get rid of it.  It NATs the source address of all connections going OUT the WH interface to the WH interface address.  If you did not have a route in place before, that might have appeared to fix some routing, but it was really just making things appear to be coming from the WH subnet.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • S Offline
            Slicster
            last edited by

            @Derelict:

            It's wrong.  Get rid of it.  It NATs the source address of all connections going OUT the WH interface to the WH interface address.  If you did not have a route in place before, that might have appeared to fix some routing, but it was really just making things appear to be coming from the WH subnet.

            It's gone now and I'm on automatic so here is what appears.  (see attached)

            ![new nat.JPG](/public/imported_attachments/1/new nat.JPG)
            ![new nat.JPG_thumb](/public/imported_attachments/1/new nat.JPG_thumb)

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              OK.  It did not pick up the NAT for the routed subnet.  You should have a gateway defined in pfSense for 192.168.253.18 and a route defined for 10.96.16.0 255.255.248.0 with that gateway as the destination. If NAT still doesn't have an entry for the 10.96.16.0/21 you'll need to add one using hybrid or manual mode.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • S Offline
                Slicster
                last edited by

                @Derelict:

                OK.  It did not pick up the NAT for the routed subnet.  You should have a gateway defined in pfSense for 192.168.253.18 and a route defined for 10.96.16.0 255.255.248.0 with that gateway as the destination. If NAT still doesn't have an entry for the 10.96.16.0/21 you'll need to add one using hybrid or manual mode.

                The route was already there and when the NAT is on Automatic, the 10.96.16.0/21 shows up but I have no communication until I add the manual NAT  "EM3, any, *, *, *, EM3 address, *, YES".

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  Dude.  Look at the automatic NAT screen you posted.  The NAT entry for 10.96.16.0/21 is not there.

                  I am telling you you are doing it wrong. You can either listen or not. If you are going to just dismiss what I say just let me know so I can stop wasting my time.

                  There is a very good reason adding that NAT entry makes some connectivity happen but doesn't fix everything as I explained above.

                  Get rid of the NAT entry for the WH interface and add a hybrid Outbound NAT rule for the 10.96.16/21 subnet on WAN.

                  Then post how you configured the routes and gateway in System > Routing.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    Slicster
                    last edited by

                    @Derelict:

                    Dude.  Look at the automatic NAT screen you posted.  The NAT entry for 10.96.16.0/21 is not there.

                    I am telling you you are doing it wrong. You can either listen or not. If you are going to just dismiss what I say just let me know so I can stop wasting my time.

                    There is a very good reason adding that NAT entry makes some connectivity happen but doesn't fix everything as I explained above.

                    Get rid of the NAT entry for the WH interface and add a hybrid Outbound NAT rule for the 10.96.16/21 subnet on WAN.

                    Then post how you configured the routes and gateway in System > Routing.

                    Sorry about that, the screenshot was from when I was testing.  Here is the latest screenshot but I'm not sure I understand if you still want me to add anything manual since it shows up on the WAN?

                    ![new nat hybrid.JPG](/public/imported_attachments/1/new nat hybrid.JPG)
                    ![new nat hybrid.JPG_thumb](/public/imported_attachments/1/new nat hybrid.JPG_thumb)

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      Slicster
                      last edited by

                      I'm going to do another test because I'm beginning to this it might have something to do with the pfSense and the fact that it's been running for a long time and that there may be some bad configuration we don't see.  This is standard routing so it should be simple.  I'm going to take another device we have, install a fresh copy and start the config from scratch.  In the meantime, I'm still opened to suggestions cause it would be great to fix it rather then start over.  Thanks.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        Yeah.  Post how you configured the gateway and the route like I asked for in the previous message.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          Slicster
                          last edited by

                          Looks like this one for the books because I was able to get everything working from a fresh install.  I'm guessing there was an inherited setting from all the past upgrades that we weren't seeing in the WebConfigurator.  All the settings are now identical to the configuration I posted earlier with Automatic NAT and it worked right away.  Same configuration, same rules, same subnets, same connections on nearly identical hardware.

                          Thanks for  your help.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.